Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18431] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and inclu…
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77693] The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the use…
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75797] The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it …
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19760] The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Sit…
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This req…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74851] The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its …
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74928] The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its impo…
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19718] The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin Word…
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing att…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-19632] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-74932] The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it…
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de escalada de privilegios en ShopEngine Elementor WooCommerce Builder
El plugin ShopEngine Elementor WooCommerce Builder para WordPress (versiones hasta 4.9.4) contiene una vulnerabilidad de escalada de privilegios (CVSS 7.2) en la función rum_importer() que permite a atacantes ejecutar acciones administrativas sin validación de permisos. Afecta a tiendas en línea en México y LATAM que utilicen este componente para gestionar productos y opciones de WooCommerce. Un atacante puede modificar configuraciones altas, crear cuentas administrativas o inyectar código malicioso en la base de datos.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de inyección SQL en plugin All-in-One WP Migration and Backup
El plugin All-in-One WP Migration and Backup para WordPress (versiones hasta 7.109) contiene una vulnerabilidad de inyección SQL en la funcionalidad de restauración de archivos, explotable sin autenticación debido a escaping insuficiente de parámetros. Afecta a miles de sitios WordPress en LATAM que utilizan este plugin para migraciones y backups, permitiendo a atacantes ejecutar consultas SQL arbitrarias y comprometer bases de datos completas.
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Total Donations para WordPress (CVE-2026-78570)
El plugin Total Donations para WordPress (versiones hasta 2.0.5) contiene una vulnerabilidad de escalada de privilegios con puntuación CVSS 9.8 que permite a atacantes no autenticados obtener permisos de administrador. Esto afecta directamente a sitios de ONG, iglesias y organizaciones benéficas en LATAM que dependen de este plugin para recaudación de fondos. La explotación no requiere autenticación previa, aumentando significativamente el riesgo de compromisos totales del sitio.
M Alto vulnerabilidad
25/08/2026
Inyección de Objetos PHP en plugin Kalles Addons para WordPress (CVE-2026-78572)
El plugin Kalles Addons para WordPress contiene una vulnerabilidad alta de inyección de objetos PHP (CVSS 8.1) en todas las versiones hasta la 1.0.6. Atacantes no autenticados pueden inyectar objetos maliciosos mediante deserialización de entrada no validada. El impacto depende de cadenas POP presentes en otros plugins o temas instalados, siendo de alto riesgo en tiendas WooCommerce y sitios corporativos de LATAM que usen extensiones adicionales.
M Alto vulnerabilidad
25/08/2026
Inyección SQL alta en plugin Readabler para WordPress afecta versiones hasta 2.0.18
El plugin Readabler para WordPress contiene una vulnerabilidad de inyección SQL que afecta todas las versiones anteriores a 2.0.18, permitiendo a atacantes no autenticados ejecutar consultas SQL maliciosas para extraer información sensible de bases de datos. Esta vulnerabilidad representa un riesgo alto para sitios WordPress en LATAM que alojan contenido confidencial, datos de clientes o información empresarial alta.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78562] The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a…
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78563] The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi…
The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78566] The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc…
The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other …
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78568] The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i…
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive informa…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-16601] The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vu…
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete extension filtering without MIME-type checks or upload capability verification before …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18323] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w…